Jobs and Careers
SE

Principal Security Engineer - IAM

SECU
United Statesfull_timeVerifiedPosted 21 Mar 2025

About the role

If you are motivated and believe in the credit union philosophy of "People Helping People," join our team!

Position Overview:

The Principal Security Engineer - IAM is a strategic and technical authority responsible for driving the vision, design, and evolution of SECU’s Identity and Access Management (IAM) program.

This role serves as a distinguished SME and advisor, leading enterprise-wide initiatives to enhance Privileged Access Management (PAM), Single Sign-On (SSO), Identity Governance and Administration (IGA), Multi-Factor Authentication (MFA), Active Directory (AD), Customer Identity and Access Management (CIAM), and other IAM solutions.

As a principal engineer, this individual will design and implement cutting-edge IAM frameworks, develop automation strategies, and ensure alignment with security, compliance, and regulatory requirements. They will partner with architects, senior leadership, security teams, and business units to help define IAM roadmaps, mitigate identity risks, and drive innovation in identity security.

This role will also provide technical mentorship, thought leadership, and influence across the organization, ensuring IAM best practices are embedded in enterprise security strategy. The Principal Cyber Security Engineer will lead cross-functional IAM initiatives, collaborate with industry peers, and contribute to the long-term cybersecurity resilience.

The principal engineer may be required, based on the overall size and available competencies within the IAM team, to assume responsibility for certain functions that would normally be addressed by other roles in larger enterprises.

Responsibilities:

  • (30%) Facilitate and lead efforts to design, plan, enhance, and test all IAM technologies used throughout SECU. Including capacity planning for future systems requirements and new technology.

  • (30%) Drive collaboration with cross-functional teams and leadership to ensure technology security solutions are in alignment with organizational strategic goals.

  • (10%) Lead governance and compliance initiatives to develop and maintain security standards in compliance with regulations and best practices. 

  • (10%) Stay abreast of emerging trends, technologies, and best practices in cybersecurity. Evaluate new tools and methodologies, pilot innovative solutions, and drive continuous improvement initiatives within cybersecurity.

  • (10%) Serve as an escalation resource for technical support of information security technologies providing expert problem analysis and resolution.

  • (10%) Provide mentorship, coaching, and guidance to junior and mid-level cybersecurity engineers including certification guidance. Foster a culture of collaboration, knowledge sharing, and continuous improvement within the cybersecurity team.

  • Responsibilities will include participation in special assignments and cross-functional initiatives as required.

Required Education & Experience (Knowledge, Skills, & Abilities):

  • Candidate must live in North Carolina or contiguous state.
  • Bachelors degree in Computer Science, Information Technology, Cyber Security, or related field.
    • Additional 5 years of relevant experience can be considered in lieu of degree.
  • Minimum 10 year of experience in related field.
  • IAM Solutions
    • Mastery of three or more IAM solutions such as PAM, SSO, Directory Services, IGA, CIAM, and MFA.
    • Experience in designing and implementing advanced integrations between multiple IAM solutions.
    • Knowledge and experience with cloud directories such as Entra ID, AWS Directory Service, and Google Cloud Identity.
    • Experience with hybrid IAM environments and cloud-to-cloud identity integration.
    • Advanced experience with APIs and understanding of how they are used to integrate IAM systems with other applications.
  • Authentication and Authorization Protocols
    • Mastery of authentication and authorization protocols such as OAuth2.0, OIDC (OpenID Connect), SAML (Security Assertion Markup Language), LDAP (Lightweight Directory Access Protocol), Kerberos, and XACML (eXtensible Access Control Markup Language).
  • IAM Governance and Compliance
    • Experience with and implementation of IAM governance frameworks and standards such as NIST, ISO 27001, SOX, and GDPR.
    • Experience with audit and compliance reporting.
  • User Lifecycle Management
    • Experience in designing and implementing provisioning and de-provisioning processes for user accounts, including Joiner-Mover-Leaver (JML) processes.
    • Experience with designing and automation of user lifecycl

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

SECU

View company profile →